T09 · Insecure Skill Coding Practices
- Location
wrapper.py:196- Finding
Route Messages and Sensitive Travel Logs Are Uploaded by Default
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
NavClaw is a real navigation helper, but it asks agents to reuse stored credentials and can automatically send detailed route logs to Mattermost without a strong per-run consent boundary.
Install only if you are comfortable with Amap receiving your route queries and, if Mattermost is configured, your route summaries and logs being posted to the configured channel. Prefer local-only use with --no-send, do not let the agent search general memory for secrets, store API keys in a proper secret manager or environment variables instead of config.py, and verify any Mattermost URL is HTTPS and trusted before enabling posting.
wrapper.py:196Route Messages and Sensitive Travel Logs Are Uploaded by Default
wrapper.py:52Unvalidated Mattermost Base URL Can Expose Bot Credentials and Travel Data
SKILL_EN.md:22Skill Instructions Direct the Agent to Search General Memory for Credentials
requirements.txt:1Third-Party Dependency Is Not Reproducibly Pinned
The README explicitly instructs the agent to search memory for an existing API key and reuse it before asking the user. This encourages cross-context secret retrieval and reuse, which can cause an agent to access stored credentials beyond the user's immediate, explicit consent and increases the risk of secret exfiltration or misuse.
The installation prompt directs the agent to look for Mattermost connection secrets in memory or configuration and use them if found. This is dangerous because it trains the agent to discover and operationalize stored tokens automatically, which weakens least-privilege boundaries and can enable unauthorized messaging or token abuse.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
[](https://www.python.org/)
[](https://clawhub.ai/AI4MSE/navclaw)
**Intelligent route planner** — standalone or powered by OpenClaw. Congestion avoidance, exhaustive route optimization, iOS & Android deep links that open your navigation app in one tap.Bonus toolbox like weather, POI search, geocoding, district query, etc.(note Bonus toolbox setup needs to update SKILL_EN.md, see github project for details) Currently supports Amap, more platforms coming
First supported navigation platform: **Amap** · More coming soon
The stated purpose is navigation, but the skill also instructs sending results and log files to Mattermost and handling external chat credentials. This materially expands the data-flow surface beyond navigation and can cause user locations, route details, and logs to be transmitted to third-party systems without a clear, upfront declaration.
This line asks the agent to obtain Mattermost bot credentials from memory, config, or the user and write them into config.py. Bot tokens can grant posting or file-upload rights to organizational chat systems, so harvesting and persisting them creates significant risk of unauthorized messaging, data leakage, and credential compromise.
The README advertises a natural-language trigger that is broad enough to encourage automatic execution from ordinary conversation. In an agent setting, ambiguous trigger phrases can cause unintended invocation from user messages or forwarded content, leading the agent to run tools without a strong confirmation boundary.
The README recommends updating long-term memory or creating a skill so the behavior persists and can be triggered later. In combination with broad natural-language activation and secret-handling guidance, this persistence makes the skill more dangerous because risky behavior and credential reuse rules survive beyond the initial installation context.
3. 复制 `config_example.py` → `config.py`,填入 Amap API Key
Copy `config_example.py` → `config.py`, fill in your Amap API key
4. 更新 OpenClaw 的长期记忆或制作技能
Update OpenClaw's long-term memory or create a skill
5. 直接说 / Just say: *"从北京南站到广州南站导航"*
### 独立使用 / Standalone
The long-term memory template defines an auto-execution trigger for phrases like navigating from one place to another, but does not impose clear constraints or a confirmation gate. Persisting this behavior in memory increases the chance of accidental or prompt-injected tool execution across future sessions.
The instructions tell the agent to place the user's Amap API key into config.py, but do not warn about the security implications of storing credentials in a local file. In agent environments, this can normalize insecure secret handling and make later leakage via logs, memory, backups, or workspace access more likely.
The README advertises Mattermost integration and automatic sending of navigation results without clearly warning that route details, destinations, and potentially sensitive travel patterns may be transmitted to an external server. In a navigation context, origin/destination data can reveal highly sensitive personal information such as home, work, or travel habits.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. Clone NavClaw into your OpenClaw project directory, or place it anywhere on your OpenClaw server
2. Copy `config_example.py` → `config.py`, fill in your Amap API key
3. Update OpenClaw's long-term memory or create a skill
4. Just say: *"Navigate from Beijing South Station to Guangzhou South Station"*
### Standalone
The README explicitly tells the agent/user to write an Amap API key into config.py, which is described as a local file-based configuration. Storing secrets in plaintext increases the risk of accidental disclosure through local file access, backups, logs, screenshots, or later commits, especially in an agent workflow that may edit files automatically.
The skill declares no explicit tool scope even though its documented behavior includes file writes and outbound network access. Without clear permission boundaries, an agent or reviewer cannot reliably understand or constrain what the skill is allowed to do, increasing the chance of unintended data writes or data exfiltration.
The skill asks for origin/destination and an Amap API key, but does not clearly warn users that location data will be sent to external routing services. Location information is sensitive, and users need informed consent before their travel requests are transmitted off-platform.
The skill explicitly tells the agent to search memory for a previously provided Amap API key and reuse it in configuration. Reusing secrets from memory without fresh, context-specific consent violates least-privilege principles and risks unauthorized credential use or unintended disclosure.
The trigger phrase "drive to [destination]" is broad enough to match ordinary conversation, making accidental invocation more likely. In this skill, accidental invocation is more dangerous because execution may perform external API calls, use stored credentials, and share outputs to other platforms.
The workflow and backup instructions describe posting route results and log attachments to Mattermost or reading log contents back into chat, but the description lacks a clear warning that this sharing occurs. Logs can contain sensitive route details, timestamps, identifiers, or debugging data, so undisclosed reposting significantly increases privacy and data leakage risk.
The fallback behavior tells the agent to read log contents and send them to the user if attachments are not possible. Logs frequently contain more information than intended for end users, including request parameters, file paths, tokens, errors, and route history, so copying them into chat increases the chance of sensitive data exposure.
The setup instructions tell the agent to ask for Mattermost bot credentials if missing and write them into config.py. Having an agent collect and persist chat-platform credentials in a general configuration file creates significant secret-handling risk, including accidental exposure through files, logs, version control, or later message forwarding.
The skill explicitly instructs the agent to retrieve an Amap API key from memory and later persist credentials into config.py. Asking an agent to mine prior context or stored memory for secrets and write them to disk expands the skill from navigation into credential handling, creating risk of unauthorized secret reuse, accidental disclosure, and long-term persistence of sensitive data.
Directing the agent to retrieve credentials from memory/config or prompt for them creates a secret-access workflow inside a navigation skill. That is dangerous because the agent may access previously stored secrets outside the current task scope and persist them in less secure locations.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
**Workflow**:
Calls `wrapper.py --origin "origin" --dest "destination"`, goes through a five-stage planning process (Wide Search → Fine Filter → Deep Processing → Iterative Optimization → Route Finalization), generates a large number of route options (including detour optimizations), and automatically sends 3 messages to the chat platform + log attachment:
- Message 1 — full comparison table
- Message 2 — quick navigation links
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
**Workflow**:
Calls `wrapper.py --origin "origin" --dest "destination"`, goes through a five-stage planning process (Wide Search → Fine Filter → Deep Processing → Iterative Optimization → Route Finalization), generates a large number of route options (including detour optimizations), and automatically sends 3 messages to the chat platform + log attachment:
- Message 1 — full comparison table
- Message 2 — quick navigation links
The skill describes sending route information and logs to Mattermost or other chat tools, but it does not warn that logs may contain sensitive location data, tokens, or debugging details. Route origins, destinations, and attached logs can reveal personal travel patterns or operational information if forwarded broadly.
The skill adds Mattermost bot posting and direct file-upload behavior that is not necessary for core route computation. That broadens the capability surface to external messaging APIs, increasing the chance of unintended data exfiltration, spam, or misuse of bot credentials if the agent is induced to post sensitive content or logs.
No suspicious patterns detected.